ID:5610 - Exploit for Security Features in wget - CVE-2016-4971

 
Main Vulnerability Database Exploits ID:5610 - Exploit for Security Features in wget - CVE-2016-4971

ID:5610 - Exploit for Security Features in wget - CVE-2016-4971

Published: June 17, 2021


Vulnerability identifier: #VU32275
Vulnerability risk: High
CVE-ID: CVE-2016-4971
CWE-ID: CWE-254
Exploitation vector: Remote access
Vulnerable software:
wget

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.


Remediation

Install update from vendor's website.